Antestor | 26.03.2012 16:44 | Hi Kira, danke für deinen Support! :party:
Noch kurz zum Auftreten meines Problems: Ich merkte gestern morgen, dass eine Verknüpfung aus dem Startmenü nicht mehr funktionierte (Corel Draw). Es wurde immer eine Installations-CD gefordert. Ich dachte mir nichts dabei. Abends kam dann die Meldung bei Antivir. Habe die Berichte des Fundes hier mal geloggt:
Antivir Code:
25.03.2012 22:40 [Guard] Malware gefunden
In der Datei 'C:\Users\Antestor\AppData\Local\Temp\KF3IHuWPMxhUNn.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen' [trojan]
gefunden.
Ausgeführte Aktion: Datei löschen
25.03.2012 22:40 [Guard] Malware gefunden
In der Datei 'C:\Users\Antestor\AppData\Local\Temp\KF3IHuWPMxhUNn.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen' [trojan]
gefunden.
Ausgeführte Aktion: Datei löschen
25.03.2012 22:40 [Guard] Malware gefunden
In der Datei 'C:\Users\Antestor\AppData\Local\Temp\KF3IHuWPMxhUNn.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.XPACK.Gen' [trojan]
gefunden.
Ausgeführte Aktion: Datei löschen Hatte ich installier aber nie im Einsatz. Habs deinstalliert! Ebenfalls deinstalliert. Hier das Logfile! Code:
OTL logfile created on: 26.03.2012 08:02:58 - Run 4
OTL by OldTimer - Version 3.2.39.2 Folder = O:\
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
4,00 Gb Total Physical Memory | 2,25 Gb Available Physical Memory | 56,14% Memory free
8,00 Gb Paging File | 5,94 Gb Available in Paging File | 74,33% Paging File free
Paging file location(s): y:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 69,23 Gb Total Space | 10,88 Gb Free Space | 15,71% Space Free | Partition Type: NTFS
Drive O: | 31,51 Gb Total Space | 14,19 Gb Free Space | 45,04% Space Free | Partition Type: NTFS
Drive S: | 7,38 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive Y: | 397,26 Gb Total Space | 53,22 Gb Free Space | 13,40% Space Free | Partition Type: NTFS
Computer Name: GRAMHEIM-PC | User Name: Antestor | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.03.25 23:30:52 | 000,593,920 | ---- | M] (OldTimer Tools) -- O:\OTL.exe
PRC - [2012.03.16 00:44:42 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012.01.13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012.01.13 14:53:18 | 000,460,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011.12.13 20:11:52 | 000,273,528 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
PRC - [2011.12.12 16:51:02 | 000,095,144 | ---- | M] (Binary Fortress Software) -- C:\Program Files (x86)\DisplayFusion\AppHookx86.exe
PRC - [2011.01.27 17:51:05 | 002,253,688 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
PRC - [2010.03.26 09:40:46 | 005,805,216 | ---- | M] (Salfeld Computer) -- C:\Windows\tray\wintmr.exe
PRC - [2010.03.26 09:40:44 | 005,558,432 | ---- | M] (Salfeld Computer) -- C:\Windows\SysWOW64\cc32\webtmr.exe
PRC - [2010.01.27 18:00:16 | 001,595,032 | ---- | M] (Salfeld Computer) -- C:\Windows\SysWOW64\cchservice.exe
PRC - [2010.01.22 21:57:08 | 000,395,824 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnat.exe
PRC - [2010.01.22 21:56:46 | 000,064,048 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Player\hqtray.exe
PRC - [2010.01.22 21:56:44 | 000,334,384 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnetdhcp.exe
PRC - [2010.01.22 21:56:28 | 000,113,200 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
PRC - [2010.01.22 21:00:48 | 000,563,760 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
PRC - [2009.11.12 06:42:56 | 000,362,032 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
PRC - [2009.11.12 06:42:20 | 005,140,960 | ---- | M] (Acronis) -- C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
PRC - [2009.09.24 08:50:10 | 003,520,256 | ---- | M] (Ghisler Software GmbH) -- C:\Program Files (x86)\totalcmd\TOTALCMD.EXE
PRC - [2009.07.21 15:34:28 | 000,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2009.05.13 17:48:18 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2009.03.02 14:08:43 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2007.04.24 20:19:54 | 003,581,680 | ---- | M] (Stardock) -- C:\Program Files (x86)\Stardock\ObjectDock\ObjectDock.exe
PRC - [2007.03.08 19:48:16 | 001,081,344 | ---- | M] (Pantone & X-Rite) -- C:\Program Files (x86)\Pantone\hueyPRO\hueyPROTray.exe
PRC - [2003.06.30 18:30:28 | 000,315,392 | ---- | M] () -- C:\Program Files (x86)\ScanWizard 5\ScannerFinder.exe
========== Modules (No Company Name) ==========
MOD - [2012.03.16 00:44:42 | 001,014,744 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\js3250.dll
MOD - [2012.02.18 15:15:00 | 008,527,008 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2010.01.22 21:57:04 | 000,970,288 | ---- | M] () -- C:\Program Files (x86)\VMware\VMware Player\libxml2.dll
MOD - [2010.01.22 21:56:46 | 000,068,656 | ---- | M] () -- C:\Program Files (x86)\VMware\VMware Player\zlib1.dll
MOD - [2009.12.12 16:12:03 | 000,141,824 | ---- | M] () -- C:\Program Files (x86)\WinRAR\rarext.dll
MOD - [2009.09.21 01:32:26 | 000,160,256 | ---- | M] () -- C:\PROGRA~2\TCUP~1\PLUGINS\Library\TCUPSH~1.DLL
MOD - [2009.02.20 06:53:54 | 000,053,248 | ---- | M] () -- C:\Program Files (x86)\Free Download Manager\Firefox\Extension\components\vmsfdmff.dll
MOD - [2007.04.24 16:22:12 | 000,112,400 | ---- | M] () -- C:\Program Files (x86)\Stardock\ObjectDock\DockShellHook.dll
MOD - [2007.04.23 01:19:28 | 000,026,392 | ---- | M] () -- C:\Program Files (x86)\Stardock\ObjectDock\Docklets\Calendar\Calendar.dll
MOD - [2007.04.21 14:47:52 | 000,059,592 | ---- | M] () -- C:\Program Files (x86)\Stardock\ObjectDock\zlib.dll
MOD - [2007.04.19 15:23:48 | 000,095,944 | ---- | M] () -- C:\Program Files (x86)\Stardock\ObjectDock\CrashRpt.dll
MOD - [2004.07.26 20:03:50 | 000,249,856 | ---- | M] () -- C:\Program Files (x86)\ScanWizard 5\SFRes.dll
MOD - [2003.06.30 18:30:28 | 000,315,392 | ---- | M] () -- C:\Program Files (x86)\ScanWizard 5\ScannerFinder.exe
MOD - [2002.11.19 15:11:40 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\Common Files\Stardock\ODImg.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2009.09.24 00:28:02 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2012.01.13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011.07.15 17:28:31 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011.01.27 17:51:05 | 002,253,688 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.01.27 18:00:16 | 001,595,032 | ---- | M] (Salfeld Computer) [Auto | Running] -- C:\Windows\SysWOW64\cchservice.exe -- (Windows-CCHook-Service)
SRV - [2010.01.22 21:57:08 | 000,395,824 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnat.exe -- (VMware NAT Service)
SRV - [2010.01.22 21:56:44 | 000,334,384 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2010.01.22 21:56:28 | 000,113,200 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe -- (VMAuthdService)
SRV - [2010.01.22 21:00:48 | 000,563,760 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe -- (VMUSBArbService)
SRV - [2010.01.08 12:33:12 | 002,480,048 | ---- | M] (Acronis) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv)
SRV - [2009.11.12 06:43:16 | 000,894,544 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2009.10.12 14:32:24 | 000,191,024 | ---- | M] (VMware, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\VMware\VMware Player\vmware-ufad.exe -- (ufad-ws60)
SRV - [2009.07.21 15:34:28 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009.07.14 01:15:34 | 000,730,264 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWOW64\ksupmgr.exe -- (ksupmgr)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.05.13 17:48:18 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011.12.10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.12.17 00:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2010.11.20 15:34:04 | 000,360,832 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm)
DRV:64bit: - [2010.11.20 15:34:04 | 000,194,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:35:34 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb)
DRV:64bit: - [2010.11.20 13:35:22 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.09.29 21:09:14 | 000,027,176 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggsemc.sys -- (ggsemc)
DRV:64bit: - [2010.09.29 21:09:14 | 000,013,352 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggflt.sys -- (ggflt)
DRV:64bit: - [2010.08.16 18:21:38 | 000,440,064 | ---- | M] (Hauppauge Computer Works, Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hcw88vid.sys -- (hcw88vid)
DRV:64bit: - [2010.08.16 18:21:34 | 000,259,456 | ---- | M] (Hauppauge Computer Works, Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hcw88bda.sys -- (hcw88bda)
DRV:64bit: - [2010.08.16 18:21:30 | 000,339,968 | ---- | M] (Hauppauge Computer Works, Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hcw88tse.sys -- (HCW88TSE)
DRV:64bit: - [2010.08.16 18:21:26 | 000,015,872 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hcw88rc5.sys -- (hcw88rc5)
DRV:64bit: - [2010.01.22 21:58:24 | 000,018,480 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\VMparport.sys -- (VMparport)
DRV:64bit: - [2010.01.22 21:58:22 | 000,068,656 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmx86.sys -- (vmx86)
DRV:64bit: - [2010.01.22 21:58:20 | 000,029,744 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VMkbd.sys -- (vmkbd)
DRV:64bit: - [2010.01.22 21:58:16 | 000,080,944 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmci.sys -- (vmci)
DRV:64bit: - [2010.01.22 21:58:16 | 000,030,256 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV:64bit: - [2010.01.22 21:00:44 | 000,038,960 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hcmon.sys -- (hcmon)
DRV:64bit: - [2010.01.22 17:13:00 | 000,037,680 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmusb.sys -- (vmusb)
DRV:64bit: - [2010.01.22 17:12:58 | 000,045,104 | R--- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetbridge.sys -- (VMnetBridge)
DRV:64bit: - [2010.01.22 17:12:58 | 000,020,016 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vmnetadapter.sys -- (VMnetAdapter)
DRV:64bit: - [2010.01.08 12:33:13 | 000,251,488 | ---- | M] (Acronis) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\afcdp.sys -- (afcdp)
DRV:64bit: - [2010.01.08 12:33:11 | 001,477,728 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpm258.sys -- (tdrpman258) Acronis Try&Decide and Restore Points filter (build 258)
DRV:64bit: - [2010.01.08 12:33:10 | 000,943,712 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter)
DRV:64bit: - [2010.01.08 12:33:01 | 000,257,120 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman)
DRV:64bit: - [2009.12.08 23:23:57 | 000,074,880 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2009.10.23 13:19:20 | 000,043,552 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\JulaWDM.sys -- (JulaWDM.sys)
DRV:64bit: - [2009.10.23 13:19:18 | 000,058,400 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\Jula.sys -- (Jula.sys)
DRV:64bit: - [2009.10.07 20:26:24 | 000,115,312 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\jraid.sys -- (JRAID)
DRV:64bit: - [2009.09.24 01:01:24 | 006,175,744 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2008.09.17 15:14:00 | 000,012,744 | R--- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Entech64.sys -- (ENTECH64)
DRV:64bit: - [2008.05.16 11:33:06 | 000,158,760 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016mdm.sys -- (s0016mdm)
DRV:64bit: - [2008.05.16 11:33:06 | 000,151,592 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016unic.sys -- (s0016unic)
DRV:64bit: - [2008.05.16 11:33:06 | 000,137,256 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016mgmt.sys -- (s0016mgmt) Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM)
DRV:64bit: - [2008.05.16 11:33:06 | 000,136,744 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016obex.sys -- (s0016obex)
DRV:64bit: - [2008.05.16 11:33:06 | 000,034,344 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016nd5.sys -- (s0016nd5)
DRV:64bit: - [2008.05.16 11:33:04 | 000,019,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016mdfl.sys -- (s0016mdfl)
DRV:64bit: - [2008.05.16 11:32:56 | 000,115,240 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016bus.sys -- (s0016bus)
DRV:64bit: - [2007.07.24 04:53:04 | 000,125,992 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PnP680r.sys -- (Pnp680r)
DRV:64bit: - [2005.03.29 02:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV - [2009.10.12 14:31:04 | 000,032,816 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Program Files (x86)\VMware\VMware Player\vstor2-ws60.sys -- (vstor2-ws60)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2008.03.19 17:14:52 | 000,015,872 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\BurnInTest\DirectIo.sys -- (DIRECTIO)
DRV - [2006.01.13 15:00:52 | 000,015,872 | ---- | M] (Flint Incorporation) [Kernel | System | Stopped] -- C:\Windows\SysWow64\drivers\vd_filedisk.sys -- (VD_FileDisk)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page =
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 15 7D 9F C5 D2 0A CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.useDBForOrder: ""
FF - prefs.js..browser.startup.homepage: "hxxp://www.google.de"
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files (x86)\TVUPlayer\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.669: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.669: c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.669: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.669: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.669: c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Antestor\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.12.13 20:13:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.28\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.03.16 00:44:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.28\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.03.16 00:44:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011.12.13 20:12:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins [2011.12.13 20:14:03 | 000,000,000 | ---D | M]
[2010.01.19 23:02:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Antestor\AppData\Roaming\mozilla\Extensions
[2010.01.19 23:02:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Antestor\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012.03.26 07:51:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Antestor\AppData\Roaming\mozilla\Firefox\Profiles\yu5646sy.default\extensions
[2012.02.21 21:50:03 | 000,000,000 | ---D | M] (Easy YouTube Video Downloader) -- C:\Users\Antestor\AppData\Roaming\mozilla\Firefox\Profiles\yu5646sy.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}
[2011.12.28 19:17:55 | 000,000,000 | ---D | M] (Web Developer) -- C:\Users\Antestor\AppData\Roaming\mozilla\Firefox\Profiles\yu5646sy.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2012.02.21 21:50:04 | 000,000,000 | ---D | M] (Fast Video Download (with SearchMenu)) -- C:\Users\Antestor\AppData\Roaming\mozilla\Firefox\Profiles\yu5646sy.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
[2010.03.20 13:21:56 | 000,000,000 | ---D | M] (Firefox Throttle) -- C:\Users\Antestor\AppData\Roaming\mozilla\Firefox\Profiles\yu5646sy.default\extensions\{ca8b7b3d-b6e6-438f-b935-601b3de48d66}
[2010.05.07 18:00:07 | 000,000,000 | ---D | M] (Torbutton) -- C:\Users\Antestor\AppData\Roaming\mozilla\Firefox\Profiles\yu5646sy.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
[2011.06.24 21:12:41 | 000,000,000 | ---D | M] (Firebug) -- C:\Users\Antestor\AppData\Roaming\mozilla\Firefox\Profiles\yu5646sy.default\extensions\firebug@software.joehewitt.com
[2012.02.21 21:50:06 | 000,000,000 | ---D | M] (FoxyProxy Standard) -- C:\Users\Antestor\AppData\Roaming\mozilla\Firefox\Profiles\yu5646sy.default\extensions\foxyproxy@eric.h.jung
[2010.01.16 15:01:19 | 000,001,340 | ---- | M] () -- C:\Users\Antestor\AppData\Roaming\Mozilla\Firefox\Profiles\yu5646sy.default\searchplugins\wikipedia-en.xml
[2009.11.08 16:16:44 | 000,004,153 | ---- | M] () -- C:\Users\Antestor\AppData\Roaming\Mozilla\Firefox\Profiles\yu5646sy.default\searchplugins\youtube.xml
[2012.03.26 07:50:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2010.05.08 20:47:15 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.08.20 18:13:37 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.12.24 16:19:26 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.04.11 20:17:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011.11.12 12:28:13 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2010.07.07 15:19:09 | 000,000,000 | ---D | M] (Free Download Manager plugin) -- C:\PROGRAM FILES (X86)\FREE DOWNLOAD MANAGER\FIREFOX\EXTENSION
[2011.12.13 20:13:11 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011.10.03 06:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2009.11.08 17:49:41 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files (x86)\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2011.08.17 18:54:06 | 000,001,392 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
[2011.08.17 18:54:06 | 000,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
[2011.08.17 18:54:06 | 000,006,805 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
[2011.08.17 18:54:06 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml
O1 HOSTS File: ([2011.11.16 23:13:31 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (WebSpeechBHO Class) - {83A30C59-3A50-49E6-9DAF-4923C4EA3C23} - C:\Program Files (x86)\Common Files\WebSpeech.4.0\LgxIEBar.dll (G DATA Software AG)
O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll ()
O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4:64bit: - HKLM..\Run: [Eraser] C:\Programme\Eraser\Eraser.exe (The Eraser Project)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [ChicoSys] C:\Windows\SysWOW64\cc32\webtmr.exe (Salfeld Computer)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ati\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [VMware hqtray] C:\Program Files (x86)\VMware\VMware Player\hqtray.exe (VMware, Inc.)
O4 - HKCU..\Run: [CCWinTray] C:\Windows\tray\wintmr.exe (Salfeld Computer)
O4 - HKCU..\Run: [DisplayFusion] C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe (Binary Fortress Software)
O4 - HKCU..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup File not found
O4 - Startup: C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Program Files (x86)\Stardock\ObjectDock\ObjectDock.exe (Stardock)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableClock = 0
O8:64bit: - Extra context menu item: Download all with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlall.htm ()
O8:64bit: - Extra context menu item: Download selected with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlselected.htm ()
O8:64bit: - Extra context menu item: Download video with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
O8:64bit: - Extra context menu item: Download with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dllink.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Antestor\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Antestor\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 File not found
O9 - Extra Button: WebSpeech - {1CE4DE72-7FCC-4eb8-8F66-AE6A56A0A54D} - C:\Program Files (x86)\Common Files\WebSpeech.4.0\LgxIEBar.dll (G DATA Software AG)
O9 - Extra 'Tools' menuitem : Seite/Markierung vorlesen (WebSpeech) - {1CE4DE72-7FCC-4eb8-8F66-AE6A56A0A54D} - C:\Program Files (x86)\Common Files\WebSpeech.4.0\LgxIEBar.dll (G DATA Software AG)
O9 - Extra Button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files (x86)\PPLive\PPLive.exe ( )
O9 - Extra 'Tools' menuitem : PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files (x86)\PPLive\PPLive.exe ( )
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Program Files (x86)\VMware\VMware Player\x64\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Program Files (x86)\VMware\VMware Player\x64\vsocklib.dll (VMware, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E2579BE8-B389-4030-9D62-31B2CEDC2CE7}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\cdo - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {6979AAD7-86EE-481F-B591-152A33E86ECB} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.08.22 07:57:52 | 000,230,728 | R--- | M] (Konami Digital Entertainment Co., Ltd.) - S:\autorun.exe -- [ UDF ]
O32 - AutoRun File - [2008.05.30 08:54:04 | 000,000,047 | R--- | M] () - S:\Autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found
========== Files/Folders - Created Within 30 Days ==========
[2012.03.26 00:04:17 | 000,000,000 | ---D | C] -- C:\Users\Antestor\Desktop\RK_Quarantine
[2012.03.25 23:33:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.03.25 23:33:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.03.25 22:43:53 | 000,000,000 | ---D | C] -- C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check
[2012.03.25 20:00:53 | 000,000,000 | ---D | C] -- C:\Users\Antestor\Documents\AdobeStockPhotos
[2012.03.14 01:30:17 | 005,559,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2012.03.14 01:30:16 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2012.03.14 01:30:16 | 003,913,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2012.03.14 00:31:50 | 001,544,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2012.03.13 22:43:33 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll
[2012.03.13 22:43:33 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll
[2012.03.13 22:43:33 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdrmemptylst.exe
[2012.03.13 22:43:32 | 001,031,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcore.dll
[2012.03.13 22:43:32 | 000,826,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpcore.dll
[2012.03.04 15:19:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Azureus
[2012.03.04 15:19:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Azureus
[2012.02.26 10:31:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Video Joiner
[2012.02.26 10:31:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Free Video Joiner
[2011.06.20 21:04:11 | 000,925,696 | ---- | C] (GSpot Appliance Corp, a unit of GSp0t Heavy Industries) -- C:\Program Files (x86)\GSpot.exe
========== Files - Modified Within 30 Days ==========
[2012.03.26 08:07:38 | 000,003,862 | -H-- | M] () -- C:\NET.INI
[2012.03.26 08:05:33 | 000,015,024 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.03.26 08:05:33 | 000,015,024 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.03.26 08:02:45 | 000,658,728 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2012.03.26 08:02:45 | 000,619,274 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.03.26 08:02:45 | 000,108,180 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.03.26 08:02:44 | 001,506,860 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.03.26 08:02:44 | 000,131,886 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2012.03.26 07:58:40 | 000,000,103 | ---- | M] () -- C:\Windows\SysWow64\swctl.dll
[2012.03.26 07:58:06 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012.03.26 07:58:04 | 3220,578,304 | -HS- | M] () -- C:\hiberfil.sys
[2012.03.25 23:33:45 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.03.25 22:42:49 | 003,400,176 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.03.20 22:00:08 | 000,009,728 | ---- | M] () -- C:\Users\Antestor\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== Files Created - No Company Name ==========
[2012.03.26 07:53:45 | 000,002,031 | ---- | C] () -- C:\Users\Public\Desktop\VMware Player.lnk
[2012.03.26 07:53:45 | 000,001,946 | ---- | C] () -- C:\Users\Public\Desktop\ScanWizard 5.lnk
[2012.03.26 07:53:45 | 000,001,884 | ---- | C] () -- C:\Users\Public\Desktop\Scanner Configuration.lnk
[2012.03.26 07:53:45 | 000,001,658 | ---- | C] () -- C:\Users\Public\Desktop\Recuva.lnk
[2012.03.26 07:53:45 | 000,001,166 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 6.lnk
[2012.03.26 07:53:45 | 000,001,157 | ---- | C] () -- C:\Users\Public\Desktop\Wise Registry Cleaner.lnk
[2012.03.26 07:53:45 | 000,001,112 | ---- | C] () -- C:\Users\Public\Desktop\TmNationsForever.lnk
[2012.03.26 07:53:45 | 000,001,105 | ---- | C] () -- C:\Users\Public\Desktop\WaveLab LE 7.lnk
[2012.03.26 07:53:45 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\XMedia Recode.lnk
[2012.03.26 07:53:45 | 000,001,070 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012.03.26 07:53:45 | 000,001,030 | ---- | C] () -- C:\Users\Public\Desktop\Samplitude 11 Silver.lnk
[2012.03.26 07:53:45 | 000,001,023 | ---- | C] () -- C:\Users\Public\Desktop\TVUPlayer.lnk
[2012.03.26 07:53:45 | 000,000,971 | ---- | C] () -- C:\Users\Public\Desktop\TC UP.lnk
[2012.03.26 07:53:45 | 000,000,944 | ---- | C] () -- C:\Users\Public\Desktop\TrueCrypt.lnk
[2012.03.26 07:53:44 | 000,002,009 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
[2012.03.26 07:53:44 | 000,001,943 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012.03.26 07:53:44 | 000,001,921 | ---- | C] () -- C:\Users\Public\Desktop\OptiPNG-UI.lnk
[2012.03.26 07:53:44 | 000,001,920 | ---- | C] () -- C:\Users\Public\Desktop\Meine Bilder.lnk
[2012.03.26 07:53:44 | 000,001,833 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
[2012.03.26 07:53:44 | 000,001,136 | ---- | C] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2012.03.26 07:53:44 | 000,001,049 | ---- | C] () -- C:\Users\Public\Desktop\Notepad++.lnk
[2012.03.26 07:53:43 | 000,002,531 | ---- | C] () -- C:\Users\Public\Desktop\buzzroom_KeyMaker.lnk
[2012.03.26 07:53:43 | 000,002,235 | ---- | C] () -- C:\Users\Public\Desktop\Acronis One-Click Backup.lnk
[2012.03.26 07:53:43 | 000,002,070 | ---- | C] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2012.03.26 07:53:43 | 000,001,970 | ---- | C] () -- C:\Users\Public\Desktop\DVBViewer Pro DEMO.lnk
[2012.03.26 07:53:43 | 000,001,953 | ---- | C] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk
[2012.03.26 07:53:43 | 000,001,952 | ---- | C] () -- C:\Users\Public\Desktop\Kostenlose Angebote.lnk
[2012.03.26 07:53:43 | 000,001,905 | ---- | C] () -- C:\Users\Public\Desktop\DVBViewer.lnk
[2012.03.26 07:53:43 | 000,001,894 | ---- | C] () -- C:\Users\Public\Desktop\IrfanView Thumbnails.lnk
[2012.03.26 07:53:43 | 000,001,747 | ---- | C] () -- C:\Users\Public\Desktop\Eraser.lnk
[2012.03.26 07:53:43 | 000,001,234 | ---- | C] () -- C:\Users\Public\Desktop\Foxit Reader.lnk
[2012.03.26 07:53:43 | 000,001,205 | ---- | C] () -- C:\Users\Public\Desktop\Ashampoo Burning Studio 2010.lnk
[2012.03.26 07:53:43 | 000,001,139 | ---- | C] () -- C:\Users\Public\Desktop\Acronis True Image Home 2010.lnk
[2012.03.26 07:53:43 | 000,001,130 | ---- | C] () -- C:\Users\Public\Desktop\Cubase LE.lnk
[2012.03.26 07:53:43 | 000,001,129 | ---- | C] () -- C:\Users\Public\Desktop\Independence Live 3.0.lnk
[2012.03.26 07:53:43 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\hueyPRO Quick Start Guide.lnk
[2012.03.26 07:53:43 | 000,001,094 | ---- | C] () -- C:\Users\Public\Desktop\Independence 3.0.lnk
[2012.03.26 07:53:43 | 000,001,091 | ---- | C] () -- C:\Users\Public\Desktop\hueyPRO.lnk
[2012.03.26 07:53:43 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\DisplayFusion.lnk
[2012.03.26 07:53:43 | 000,001,044 | ---- | C] () -- C:\Users\Public\Desktop\Allway Sync.lnk
[2012.03.26 07:53:43 | 000,001,030 | ---- | C] () -- C:\Users\Public\Desktop\FLV Player.lnk
[2012.03.26 07:53:43 | 000,001,002 | ---- | C] () -- C:\Users\Public\Desktop\IrfanView.lnk
[2012.03.26 07:53:43 | 000,000,947 | ---- | C] () -- C:\Users\Public\Desktop\energyXT 2.5.4.lnk
[2012.03.26 07:53:43 | 000,000,928 | ---- | C] () -- C:\Users\Public\Desktop\Last.fm.lnk
[2012.03.26 07:53:43 | 000,000,702 | ---- | C] () -- C:\Users\Public\Desktop\Install WinTV v7.x CD 2.4d.lnk
[2012.03.26 07:53:42 | 000,002,064 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER © Uninstall.lnk
[2012.03.26 07:53:42 | 000,002,040 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER ©.lnk
[2012.03.26 07:53:42 | 000,001,547 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2012.03.26 07:53:42 | 000,001,352 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
[2012.03.26 07:53:42 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2012.03.26 07:53:42 | 000,001,246 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
[2012.03.26 07:53:42 | 000,001,210 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
[2012.03.26 07:53:42 | 000,001,178 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 6.lnk
[2012.03.26 07:53:41 | 000,002,309 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2012.03.26 07:53:41 | 000,002,106 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
[2012.03.26 07:53:41 | 000,002,003 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
[2012.03.26 07:53:41 | 000,001,978 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Scanner Finder.lnk
[2012.03.26 07:53:41 | 000,001,845 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2012.03.26 07:53:41 | 000,001,330 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
[2012.03.26 07:53:41 | 000,001,131 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hueyPROTray.lnk
[2012.03.26 07:53:41 | 000,000,930 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SampleTank 2.5.lnk
[2012.03.26 07:53:40 | 000,002,775 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Outlook.lnk
[2012.03.26 07:53:40 | 000,002,715 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Excel.lnk
[2012.03.26 07:53:40 | 000,002,703 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft PowerPoint.lnk
[2012.03.26 07:53:40 | 000,002,683 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Word.lnk
[2012.03.26 07:53:40 | 000,002,645 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Access.lnk
[2012.03.26 07:53:40 | 000,001,970 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2012.03.26 07:53:40 | 000,001,949 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Deinstallationsprogramm.lnk
[2012.03.26 07:53:40 | 000,001,928 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2012.03.26 07:53:40 | 000,001,759 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Eraser.lnk
[2012.03.26 07:53:40 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2012.03.26 07:53:40 | 000,000,998 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IK Multimedia Authorization Manager.lnk
[2012.03.26 07:53:39 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2012.03.26 07:53:39 | 000,002,089 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help Center.lnk
[2012.03.26 07:53:39 | 000,002,081 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge.lnk
[2012.03.26 07:53:39 | 000,002,069 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ImageReady CS.lnk
[2012.03.26 07:53:39 | 000,002,062 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS.lnk
[2012.03.26 07:53:39 | 000,001,903 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
[2012.03.26 07:53:39 | 000,001,403 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit 2.lnk
[2012.03.26 07:53:39 | 000,001,223 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Stock Photos CS3.lnk
[2012.03.26 07:53:39 | 000,001,192 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS3.lnk
[2012.03.26 07:53:39 | 000,001,137 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS3.lnk
[2012.03.26 07:53:39 | 000,001,099 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS3.lnk
[2012.03.26 07:53:39 | 000,001,027 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe InDesign CS2.lnk
[2012.03.25 23:33:45 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012.03.25 23:09:53 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012.03.18 21:11:11 | 004,194,304 | ---- | C] () -- C:\Users\Antestor\Desktop\(06) Wedding Party - To The Unknown God.mp3
[2012.01.09 22:23:31 | 000,032,184 | ---- | C] () -- C:\Windows\Irremote.ini
[2011.12.05 23:57:47 | 000,000,209 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2011.12.05 23:38:44 | 000,037,639 | ---- | C] () -- C:\Windows\alt.Irremote.ini
[2011.12.05 23:22:34 | 000,142,337 | ---- | C] () -- C:\Windows\SysWow64\Wait.exe
[2011.11.16 23:13:29 | 000,000,103 | ---- | C] () -- C:\Windows\SysWow64\swctl.dll
[2011.07.17 11:44:49 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011.07.17 11:44:14 | 000,033,019 | ---- | C] () -- C:\Windows\SysWow64\CoreAAC-uninstall.exe
[2011.07.17 11:43:16 | 000,819,200 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2011.07.17 11:43:16 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2011.01.15 23:37:27 | 000,000,016 | ---- | C] () -- C:\Windows\SysWow64\msvcsv60.dll
[2011.01.15 23:37:27 | 000,000,016 | ---- | C] () -- C:\Windows\msocreg32.dat
[2010.11.21 14:54:32 | 000,695,642 | ---- | C] () -- C:\Windows\unins000.exe
[2010.11.21 14:54:32 | 000,011,205 | ---- | C] () -- C:\Windows\unins000.dat
[2010.07.09 22:26:52 | 000,017,408 | ---- | C] () -- C:\Users\Antestor\AppData\Local\WebpageIcons.db
[2010.06.05 02:46:32 | 001,499,556 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010.04.10 20:29:47 | 000,002,892 | ---- | C] () -- C:\Windows\SysWow64\audcon.sys
[2010.04.10 20:27:45 | 000,000,051 | ---- | C] () -- C:\Windows\SysWow64\SYNSOPOS.exe.cfg
[2010.04.10 20:27:44 | 000,086,016 | ---- | C] () -- C:\Windows\SysWow64\SYNSOPOS.exe
[2010.03.29 23:22:23 | 000,000,000 | ---- | C] () -- C:\Windows\HPMProp.INI
========== LOP Check ==========
[2010.01.08 12:44:50 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Acronis
[2010.05.15 18:07:10 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Amazon
[2010.01.03 23:35:39 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Artisteer
[2009.11.21 00:07:29 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Ashampoo
[2010.05.12 22:23:57 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\BAUM Retec
[2012.02.11 14:50:06 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Canneverbe Limited
[2011.12.06 00:29:45 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\DBC2F6FD-3140-41E0-A2A1-D6BAB77D5E21__F893F7CA-8278-41DF-A76F-CAF0437A90CD__
[2012.01.04 18:44:20 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\DisplayFusion
[2011.02.19 14:26:41 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\DVDVideoSoftIEHelpers
[2010.03.06 18:34:26 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Filter Forge
[2011.02.18 22:40:37 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Filter Forge 2
[2009.11.08 17:50:10 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Foxit
[2010.05.02 10:03:04 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Foxit Software
[2012.03.26 07:54:19 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Free Download Manager
[2010.04.17 00:56:34 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\FreeStone Group
[2011.06.14 23:38:23 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\GHISLER
[2011.01.10 21:20:29 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Gutscheinmieze
[2010.01.16 16:58:04 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\HEXelon
[2011.06.14 23:38:23 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\IrfanView
[2011.06.14 23:38:23 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\KeePass
[2011.03.26 23:00:42 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\MAGIX
[2010.09.26 13:04:57 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Miranda
[2012.03.23 18:52:21 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Mp3tag
[2009.11.25 22:49:44 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Notepad++
[2011.12.23 16:01:22 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\OfficeRecovery
[2009.11.29 19:08:00 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Opera
[2009.11.15 17:12:50 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Pantone
[2010.12.11 18:38:18 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\PPLive
[2012.03.04 18:25:11 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\REAPER
[2011.09.19 19:13:41 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\SanDisk
[2010.12.23 01:02:53 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Smartelectronix
[2011.01.16 00:22:02 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Steinberg
[2009.12.03 20:26:19 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Sync App Settings
[2011.02.11 22:53:06 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\TeamViewer
[2010.01.19 23:02:43 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Thunderbird
[2012.01.04 00:11:04 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\TrueCrypt
[2011.08.22 21:46:38 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Voxengo
[2010.10.09 21:29:10 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\VST3 Presets
[2012.01.29 11:25:50 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\XMedia Recode
[2011.03.27 00:25:55 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Yellow Tools
[2010.05.26 23:31:13 | 000,000,000 | ---D | M] -- C:\Users\Antestor\AppData\Roaming\Youtube Downloader HD
[2012.02.23 22:24:53 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report > Hier die Logdatei: Code:
3DMark06 Futuremark Corporation 27.11.2009 1.1.1
3GP Player 2009 Reganam 14.03.2010 1.1
7-Zip 4.65 10.11.2009
ABBYY FineReader OCR Engine 12.11.2009
AC3Filter 1.63b Alexander Vigovsky 16.07.2011 1.63b
Acronis True Image Home Acronis 07.01.2010 152,5MB 13.0.6053
Adobe Bridge 1.0 Adobe Systems 07.11.2009 87,1MB 001.000.004
Adobe Color Common Settings Adobe Systems Incorporated 08.12.2011 9,20MB 1.0.1
Adobe ExtendScript Toolkit 2 Adobe Systems Incorporated 08.12.2011 16,4MB 2.0.2
Adobe Flash Player 10 ActiveX Adobe Systems Incorporated 07.11.2009 10.0.32.18
Adobe Flash Player 11 Plugin 64-bit Adobe Systems Incorporated 17.02.2012 6,00MB 11.1.102.62
Adobe InDesign CS2 Adobe Systems Incorporated 07.11.2009 004.000.000
Adobe Photoshop CS Adobe Systems, Inc. 07.11.2009 CS
Adobe Photoshop CS3 Adobe Systems Incorporated 14.07.2011 1.085MB 10.0
Adobe Shockwave Player 11.5 Adobe Systems, Inc. 26.11.2010 11.5.9.615
ADUSB Treiber Pre-Installation 1.0 11.05.2010
Allway Sync version 9.4.11 Botkind Inc 02.12.2009
AM Track SE MAGIX AG 14.01.2011 1.0.0.0
Amazon MP3-Downloader 1.0.9 14.05.2010
Apple Application Support Apple Inc. 19.03.2010 32,4MB 1.1.0
Apple Software Update Apple Inc. 19.03.2010 2,16MB 2.1.1.116
ArcSoft Codec ArcSoft 04.12.2011
Artisteer 2 Extensoft 02.01.2010 2.3
Ashampoo Burning Studio 2010 ashampoo GmbH & Co. KG 07.11.2009 9.12
ASIO4ALL 30.01.2010
ATI Catalyst Install Manager ATI Technologies, Inc. 07.11.2009 18,3MB 3.0.745.0
Avi2Dvd 0.6.2 TrustFm 16.07.2011 0.6.2
Avira AntiVir Personal - Free Antivirus Avira GmbH 07.11.2009
AviSynth 2.5 16.07.2011
Briz Video Joiner 19.06.2011 1,28MB
BurnInTest v6.0 Standard Passmark Software 27.11.2009 6.0
buzzroom KeyMaker buzzroom 04.12.2010 0,60MB 1.0.0
CCleaner Piriform 24.03.2012 3.16
CDBurnerXP CDBurnerXP 10.02.2012 12,7MB 4.4.0.2905
CDex extraction audio 07.11.2009
CoreAAC Audio Decoder (remove only) 16.07.2011
DisplayFusion 3.4.1 Binary Fortress Software 02.01.2012 8,52MB 3.4.1.0
DVBViewer Pro CM&V 04.01.2012 15,6MB 4.9
DVBViewer Pro DEMO CM&V 04.12.2011 9,43MB 4.8.1
DVD Shrink 3.2 DVD Shrink 01.01.2012
DVS Guitar v1.04 Dream Vortex Studio 25.09.2010
eLicenser Control Steinberg Media Technologies GmbH 09.04.2010
energyXT 2.5.4 XT Software AS 14.01.2011 8,34MB
Eraser 6.0.8.2273 The Eraser Project 23.05.2011 3,23MB 6.0.2273
ESET Online Scanner v3 10.11.2011
EZdrummer Toontrack 05.03.2011 708MB 1.2.0
EZdrummer Lite Installer Toontrack 09.01.2011 166,9MB 1.1.4
EZXCocktail Toontrack 09.01.2011 175,1MB 1.2
EZXMetalHeads Toontrack 09.03.2011 613MB 1.0.0
ffdshow [rev 3299] [2010-03-03] 16.07.2011 1.0.0.3299
Filter Forge 1.021 Filter Forge, Inc. 09.08.2010
Filter Forge 2.012 Filter Forge, Inc. 17.03.2012
FindInMidi Standardfirmenname 07.05.2011 9,20MB 1.2.0
FLV Player 2.0 (build 25) Martijn de Visser 09.11.2009 2.0 (build 25)
Foxit Reader Foxit Software Company 07.11.2009 3.1.3.1030
Free Audio CD Burner version 1.4.7 DVDVideoSoft Limited. 03.04.2011 10,7MB
Free Download Manager 3.0 FreeDownloadManager.ORG 06.07.2010
Free Video Joiner 1.1 FreeVideoJoiner.com 25.02.2012
FreeUndelete 2.1.36867.1 Recoveronix 22.12.2011 0,73MB 2.1.36867.1
Futuremark SystemInfo Futuremark Corporation 27.11.2009 3.20.1.2
G DATA Logox 4 Speechengine G DATA Software AG 11.05.2010
G DATA WebSpeech 4 G DATA Software AG 11.05.2010
Haali Media Splitter 16.07.2011
Halls Of Fame Free - Origami Edition 2.5.2 09.03.2011
HammerHead Rhythm Station 27.12.2009
hueyPRO 1.5.0 Pantone & X-Rite 14.11.2009
Hydrogen 19.11.2009
Independence Pro Software Suite 3.0 06.11.2009
Independence Pro Software Suite 3.0 Yellow Tools 11.06.2011 3.0
IrfanView (remove only) 07.11.2009
Java(TM) 6 Update 29 Sun Microsystems, Inc. 29.12.2009 95,0MB 6.0.290
JDownloader 0.9 AppWork GmbH 25.05.2011 0.9
JDownloader 0.9 AppWork GmbH 06.11.2009 0.9
JMicron JMB36X Driver JMICRON Technology Corp. 07.11.2009 1.00.0000
KeePass Password Safe 1.16 Dominik Reichl 07.11.2009 1.16
Kindersicherung 2010 Salfeld Computer GmbH 25.03.2010
Last.fm 1.5.4.27091 Last.fm 20.11.2010
LogiEdit (remove only) 09.07.2011
Magical Glass FreeStone Group 16.04.2010 v.2.0.0.2
MAGIX Screenshare MAGIX AG 25.03.2011 1,43MB 4.3.6.1987
MAGIX Speed burnR (MSI) MAGIX AG 25.03.2011 52,9MB 7.0.2.6
Malwarebytes Anti-Malware Version 1.60.1.1000 Malwarebytes Corporation 24.03.2012 17,4MB 1.60.1.1000
Microsoft .NET Framework 4 Client Profile Microsoft Corporation 04.10.2010 38,8MB 4.0.30319
Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft Corporation 04.10.2010 2,94MB 4.0.30319
Microsoft Office XP Professional Microsoft Corporation 07.11.2009 239MB 10.0.2701.01
Microsoft Silverlight Microsoft Corporation 10.02.2012 22,6MB 5.0.61118.0
Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 12.02.2012 0,29MB 8.0.61001
Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Corporation 07.11.2009 0,69MB 8.0.61000
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Corporation 06.11.2009 0,58MB 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 12.02.2012 0,59MB 9.0.30729.6161
Miranda IM 0.9.17 09.03.2011
Mozilla Firefox (3.6.28) Mozilla 15.03.2012 3.6.28 (de)
Mozilla Thunderbird 10.0.2 (x86 de) Mozilla 25.02.2012 40,1MB 10.0.2
Mp3tag v2.49a Florian Heidenreich 18.11.2011 v2.49a
MSXML 4.0 SP2 (KB954430) Microsoft Corporation 09.11.2009 1,28MB 4.20.9870.0
MSXML 4.0 SP2 (KB973688) Microsoft Corporation 24.11.2009 1,33MB 4.20.9876.0
Notepad++ 24.11.2009 5.5
ObjectDock Plus 05.01.2010
OpenAL 27.11.2009
Opera 11.61 Opera Software ASA 26.01.2012 11.61.1250
OptiPNG-UI Vincenzo Fleri 08.01.2011 1.0.0.2
Organ One v. 2.10 23.07.2010
PantsOff 2.0 Christoph Bünger Software 04.04.2010 2.0
PDFCreator Frank Heindörfer, Philip Chinery 07.11.2009 0.9.8
PPLive 1.9 Synacast 10.12.2010 1.9.47
Pro Evolution Soccer 2009 KONAMI 07.11.2009 7.564MB 1.20.0000
Pro Evolution Soccer 6 KONAMI 19.08.2011 1.455MB 1.00.0000
QuickTime Apple Inc. 19.03.2010 77,3MB 7.65.17.80
ratDVD 0.78.1444 ratDVD 27.01.2012 0.78.1444
RealPlayer RealNetworks 12.12.2011
REAPER 12.04.2010
Recuva Piriform 21.05.2011 1.40
rgc:audio sfz VSTi v1.96 18.08.2011
SampleTank FREE IK Multimedia 14.01.2011 2.5.5
Samplitude 11 Silver MAGIX AG 20.08.2011 11.0.0.0
Sansa Updater SanDisk Corporation 18.09.2011 0,57MB 1.304
ScanWizard 5 12.11.2009
SopCast 3.2.9 www.sopcast.com 10.12.2010 3.2.9
Steinberg Cubase LE 30.01.2010
Steinberg Cubase LE 5 Steinberg Media Technologies GmbH 09.04.2010 91,3MB 5.1.2
Steinberg HALionOne Steinberg Media Technologies GmbH 09.04.2010 117,7MB 1.1.0.457
Steinberg HALionOne Essential Set Steinberg Media Technologies GmbH 09.04.2010 101,7MB 1.0.1.457
Studio Devil BVC 1.1 StudioDevil 20.11.2010
SUPER © Version 2009.bld.36 (June 10, 2009) eRightSoft 15.12.2009 Version 2009.bld.36 (June 10, 2009)
TeamViewer 6 TeamViewer GmbH 10.02.2011 6.0.10194
TmNationsForever Nadeo 26.08.2011
Toontrack solo Toontrack 09.01.2011 11,3MB 1.2.2
Top Set 2.00 Aldarin 11.03.2010 2.00
Total Commander (Remove or Repair) Ghisler Software GmbH 07.11.2009 7.50a
Total Commander Ultima Prime 5.0.0.0 ULTIMA PRIME 15.01.2010 5.0.0.0
TrueCrypt TrueCrypt Foundation 07.11.2009 6.3
TVUPlayer 2.5.3.1 TVU networks 28.01.2011 2.5.3.1
Uninstall 1.0.0.1 03.04.2011 10,9MB
Unity Web Player Unity Technologies ApS 03.11.2011 12,0MB
Veetle TV 0.9.18 Veetle, Inc 18.02.2011 0.9.18
VLC media player 1.1.11 VideoLAN 22.12.2011 1.1.11
VMware Player VMware, Inc 04.06.2010 488MB 3.0.1.11056
WaveLab LE 7 Steinberg 15.01.2011 7.0.1.506
Winamp Nullsoft, Inc 07.11.2009 5.56
Windows-Treiberpaket - BAUM Retec AG USB Driver Package - V7 (02/17/2009 2.04.16) BAUM Retec AG 11.05.2010 02/17/2009 2.04.16
Windows-Treiberpaket - BAUM Retec AG USB Driver Package - V7 (02/17/2009 2.04.16) BAUM Retec AG 12.05.2010 02/17/2009 2.04.16
WinRAR 03.01.2010
WinUAE 2.3.0 Arabuusimiehet 28.08.2011 2.3.0
Wise Registry Cleaner 5.9.4 ZhiQing Soft, Inc. 11.06.2011 3,46MB 5.9.4
XMedia Recode 3.0.7.6 Sebastian Dörfler 26.01.2012 3.0.7.6
Xvid 1.2.2 final uninstall Xvid team (Koepi) 16.07.2011 1.2
yellow tools Independence Free 2.5.3 32bit 10.04.2010
Youtube Downloader HD v. 1.9 YoutubeDownloaderHD.com 25.05.2010
Zattoo 3.3.4 Beta Zattoo Inc. 13.11.2009 3.3.4 Beta
Zattoo4 4.0.5 Zattoo Inc. 08.07.2010 4.0.5 Zitat:
SuperAntiSpyware Free Edition
| Hier der Log: Code:
SUPERAntiSpyware Scan Log
hxxp://www.superantispyware.com
Generated 03/26/2012 at 11:18 AM
Application Version : 5.0.1146
Core Rules Database Version : 8377
Trace Rules Database Version: 6189
Scan type : Complete Scan
Total Scan Time : 02:43:17
Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC Off - Administrator
Memory items scanned : 781
Memory threats detected : 0
Registry items scanned : 66531
Registry threats detected : 0
File items scanned : 412304
File threats detected : 116
Adware.Tracking Cookie
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@ad.adition[2].txt [ /ad.adition ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@ad.yieldmanager[1].txt [ /ad.yieldmanager ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@ad2.adfarm1.adition[2].txt [ /ad2.adfarm1.adition ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@ad3.adfarm1.adition[1].txt [ /ad3.adfarm1.adition ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@adbrite[1].txt [ /adbrite ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@ads.adk2[2].txt [ /ads.adk2 ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@ads.medienhaus[1].txt [ /ads.medienhaus ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@adtech[1].txt [ /adtech ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@advertising[1].txt [ /advertising ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@adviva[1].txt [ /adviva ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@adx.chip[1].txt [ /adx.chip ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@apmebf[2].txt [ /apmebf ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@at.atwola[1].txt [ /at.atwola ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@atwola[2].txt [ /atwola ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@bs.serving-sys[2].txt [ /bs.serving-sys ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@content.yieldmanager[1].txt [ /content.yieldmanager ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@content.yieldmanager[2].txt [ /content.yieldmanager ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@content.yieldmanager[4].txt [ /content.yieldmanager ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@content.yieldmanager[5].txt [ /content.yieldmanager ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@content.yieldmanager[6].txt [ /content.yieldmanager ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@content.yieldmanager[7].txt [ /content.yieldmanager ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@de.at.atwola[1].txt [ /de.at.atwola ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@himedia.individuad[2].txt [ /himedia.individuad ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@imrworldwide[2].txt [ /imrworldwide ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@smartmedia.allyes[2].txt [ /smartmedia.allyes ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@specificclick[2].txt [ /specificclick ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@tacoda[1].txt [ /tacoda ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@tracking.mindshare[2].txt [ /tracking.mindshare ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@tracking.quisma[2].txt [ /tracking.quisma ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@tradedoubler[1].txt [ /tradedoubler ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@tradedoubler[2].txt [ /tradedoubler ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@traffictrack[1].txt [ /traffictrack ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@unitymedia[2].txt [ /unitymedia ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@yieldmanager[1].txt [ /yieldmanager ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@zanox-affiliate[2].txt [ /zanox-affiliate ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\antestor@zanox[1].txt [ /zanox ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\F4XZO1CC.txt [ /2o7.net ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\TBKLY9D0.txt [ /smartadserver.com ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\OP6LJ6CP.txt [ /explore.trackmania.com ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\8R91AQO4.txt [ /serving-sys.com ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\UUUFI89O.txt [ /fastclick.net ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\MDIV43ZQ.txt [ /atdmt.com ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\ZRX7TJFG.txt [ /fl01.ct2.comclick.com ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\U6I8Y19M.txt [ /explore.trackmania.com ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\5YTWHOGB.txt [ /ad.yieldmanager.com ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\M6VF0EFH.txt [ /eas.apm.emediate.eu ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\71KPFJVL.txt [ /maniahome.trackmania.com ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\VTCHGCE4.txt [ /eset.122.2o7.net ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\AWNUWIQU.txt [ /c.atdmt.com ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\LJ2PA4GJ.txt [ /ads.creative-serving.com ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\S4A00CUZ.txt [ /doubleclick.net ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\XNUDU3X7.txt [ /mediaplex.com ]
C:\Users\Antestor\AppData\Roaming\Microsoft\Windows\Cookies\AE8OQZ7S.txt [ /statcounter.com ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@clkads[4].txt [ Cookie:antestor@clkads.com/adServe/static/ ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@adx.chip[2].txt [ Cookie:antestor@adx.chip.de/ ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@tradedoubler[1].txt [ Cookie:antestor@tradedoubler.com/ ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@serving-sys[1].txt [ Cookie:antestor@serving-sys.com/ ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@advertising[2].txt [ Cookie:antestor@advertising.com/ ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@tto2.traffictrack[1].txt [ Cookie:antestor@tto2.traffictrack.de/ ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@atdmt[1].txt [ Cookie:antestor@atdmt.com/ ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@trackalyzer[1].txt [ Cookie:antestor@trackalyzer.com/ ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@clkads[3].txt [ Cookie:antestor@clkads.com/adServe/banners ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@msnportal.112.2o7[1].txt [ Cookie:antestor@msnportal.112.2o7.net/ ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@de.sitestat[1].txt [ Cookie:antestor@de.sitestat.com/idgcom-de/pcwelt/ ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@adtech[1].txt [ Cookie:antestor@adtech.de/ ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@bs.serving-sys[2].txt [ Cookie:antestor@bs.serving-sys.com/ ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@tracking.mlsat02[1].txt [ Cookie:antestor@tracking.mlsat02.de/tmobile/ ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@ad3.adfarm1.adition[1].txt [ Cookie:antestor@ad3.adfarm1.adition.com/ ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@clkads[2].txt [ Cookie:antestor@clkads.com/adServe/ ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@doubleclick[1].txt [ Cookie:antestor@doubleclick.net/ ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@traffictrack[2].txt [ Cookie:antestor@traffictrack.de/ ]
C:\USERS\ANTESTOR\AppData\Roaming\Microsoft\Windows\Cookies\Low\antestor@adfarm1.adition[2].txt [ Cookie:antestor@adfarm1.adition.com/ ]
C:\USERS\ANTESTOR\Cookies\F4XZO1CC.txt [ Cookie:antestor@2o7.net/ ]
C:\USERS\ANTESTOR\Cookies\OP6LJ6CP.txt [ Cookie:antestor@explore.trackmania.com/ ]
C:\USERS\ANTESTOR\Cookies\antestor@himedia.individuad[2].txt [ Cookie:antestor@himedia.individuad.net/ ]
C:\USERS\ANTESTOR\Cookies\antestor@ad.adition[2].txt [ Cookie:antestor@ad.adition.net/ ]
C:\USERS\ANTESTOR\Cookies\antestor@content.yieldmanager[5].txt [ Cookie:antestor@content.yieldmanager.com/ ]
C:\USERS\ANTESTOR\Cookies\antestor@adx.chip[1].txt [ Cookie:antestor@adx.chip.de/ ]
C:\USERS\ANTESTOR\Cookies\antestor@tradedoubler[1].txt [ Cookie:antestor@tradedoubler.com/ ]
C:\USERS\ANTESTOR\Cookies\antestor@adbrite[1].txt [ Cookie:antestor@adbrite.com/ ]
C:\USERS\ANTESTOR\Cookies\8R91AQO4.txt [ Cookie:antestor@serving-sys.com/ ]
C:\USERS\ANTESTOR\Cookies\antestor@smartmedia.allyes[2].txt [ Cookie:antestor@smartmedia.allyes.com/ ]
C:\USERS\ANTESTOR\Cookies\antestor@advertising[1].txt [ Cookie:antestor@advertising.com/ ]
C:\USERS\ANTESTOR\Cookies\UUUFI89O.txt [ Cookie:antestor@fastclick.net/ ]
C:\USERS\ANTESTOR\Cookies\MDIV43ZQ.txt [ Cookie:antestor@atdmt.com/ ]
C:\USERS\ANTESTOR\Cookies\ZRX7TJFG.txt [ Cookie:antestor@fl01.ct2.comclick.com/ ]
C:\USERS\ANTESTOR\Cookies\U6I8Y19M.txt [ Cookie:antestor@explore.trackmania.com/home/ ]
C:\USERS\ANTESTOR\Cookies\5YTWHOGB.txt [ Cookie:antestor@ad.yieldmanager.com/ ]
C:\USERS\ANTESTOR\Cookies\antestor@atwola[2].txt [ Cookie:antestor@atwola.com/ ]
C:\USERS\ANTESTOR\Cookies\VTCHGCE4.txt [ Cookie:antestor@eset.122.2o7.net/ ]
C:\USERS\ANTESTOR\Cookies\AWNUWIQU.txt [ Cookie:antestor@c.atdmt.com/ ]
C:\USERS\ANTESTOR\Cookies\antestor@specificclick[2].txt [ Cookie:antestor@specificclick.net/ ]
C:\USERS\ANTESTOR\Cookies\antestor@adtech[1].txt [ Cookie:antestor@adtech.de/ ]
C:\USERS\ANTESTOR\Cookies\antestor@bs.serving-sys[2].txt [ Cookie:antestor@bs.serving-sys.com/ ]
C:\USERS\ANTESTOR\Cookies\antestor@unitymedia[2].txt [ Cookie:antestor@unitymedia.de/ ]
C:\USERS\ANTESTOR\Cookies\antestor@ad3.adfarm1.adition[1].txt [ Cookie:antestor@ad3.adfarm1.adition.com/ ]
C:\USERS\ANTESTOR\Cookies\antestor@tacoda[1].txt [ Cookie:antestor@tacoda.net/ ]
C:\USERS\ANTESTOR\Cookies\antestor@de.at.atwola[1].txt [ Cookie:antestor@de.at.atwola.com/ ]
C:\USERS\ANTESTOR\Cookies\antestor@yieldmanager[1].txt [ Cookie:antestor@yieldmanager.net/ ]
C:\USERS\ANTESTOR\Cookies\antestor@apmebf[2].txt [ Cookie:antestor@apmebf.com/ ]
C:\USERS\ANTESTOR\Cookies\S4A00CUZ.txt [ Cookie:antestor@doubleclick.net/ ]
C:\USERS\ANTESTOR\Cookies\XNUDU3X7.txt [ Cookie:antestor@mediaplex.com/ ]
C:\USERS\ANTESTOR\Cookies\antestor@tracking.mindshare[2].txt [ Cookie:antestor@tracking.mindshare.de/ ]
C:\USERS\ANTESTOR\Cookies\AE8OQZ7S.txt [ Cookie:antestor@statcounter.com/ ]
C:\USERS\ANTESTOR\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\ANTESTOR@ADSERV.KWICK[2].TXT [ /ADSERV.KWICK ]
C:\USERS\ANTESTOR\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\ANTESTOR@KONTERA[1].TXT [ /KONTERA ]
C:\USERS\ANTESTOR\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\ANTESTOR@AD2.ADFARM1.ADITION[2].TXT [ /AD2.ADFARM1.ADITION ]
C:\USERS\ANTESTOR\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\ANTESTOR@EAS.APM.EMEDIATE[2].TXT [ /EAS.APM.EMEDIATE ]
C:\USERS\ANTESTOR\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\ANTESTOR@ZANOX[1].TXT [ /ZANOX ]
C:\USERS\ANTESTOR\APPDATA\ROAMING\MICROSOFT\WINDOWS\COOKIES\LOW\ANTESTOR@ZANOX-AFFILIATE[1].TXT [ /ZANOX-AFFILIATE ]
NotHarmful.Sysinternals Bluescreen Screen Saver
W:\SURVIVE\DIESDAS\BLUESCREEN\SYSINTERNALS BLUESCREEN.SCR
Trojan.Agent/Gen-Krpytik
W:\SURVIVE\DIESDAS\PACKER\WINRAR2\IWIN.SFX
Trojan.SF
W:\SURVIVE\GAMES\SF\SF.EXE
Adware.Vundo/Variant-MSFake
C:\PROGRAM FILES (X86)\BWS 4\BIN\MSVCRT3.DLL
C:\PROGRAM FILES (X86)\BIBLE WORKSHOP 4.4\BIN\MSVCRT3.DLL
Trojan.Agent/Gen-Autorun[Swisyn]
C:\PROGRAM FILES (X86)\TC UP\PLUGINS\WFX\NTFS4TC\NTFSFS.WFX Vielen Dank für deine Hilfe!! |